THREATOPS
THREAT OPSThreat News › CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table

CVE-2026-16028: Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table

medoss_secPublished 2026-09-07

<p>Posted by Robert Rothenberg on Sep 07</p>========================================================================<br /> CVE-2026-16028                                       CPAN Security Group<br /> ========================================================================<br /> <br />         CVE ID:  CVE-2026-16028<br />   Distribution:  Protocol-HTTP2<br />       Versions:  before 1.14<br /

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/664